Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-36931

Опубликовано: 25 янв. 2026
Источник: nvd
CVSS3: 6.4
EPSS Низкий

Описание

Click2Magic 1.1.5 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts in the chat name input. Attackers can craft a malicious payload in the chat name to capture administrator cookies when the admin processes user requests.

EPSS

Процентиль: 1%
0.00011
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.4
github
14 дней назад

Click2Magic 1.1.5 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts in the chat name input. Attackers can craft a malicious payload in the chat name to capture administrator cookies when the admin processes user requests.

EPSS

Процентиль: 1%
0.00011
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-79